Security update for openssl-3
This update for openssl-3 fixes the following issues: - CVE-2025-27587: timing side-channel vulnerability in the P-384 implementation when used with ECDSA (bsc#1243459). - CVE-2024-12797: Fixed that RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) - CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation (bsc#1236136)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openssl-3 fixes the following issues: - CVE-2025-27587: timing side-channel vulnerability in the P-384 implementation when used with ECDSA (bsc#1243459). - CVE-2024-12797: Fixed that RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) - CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation (bsc#1236136)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1236136
- https://bugzilla.suse.com/1236599
- https://bugzilla.suse.com/1243459
- https://www.suse.com/security/cve/CVE-2024-12797
- https://www.suse.com/security/cve/CVE-2024-13176
- https://www.suse.com/security/cve/CVE-2025-27587
- https://www.suse.com/support/update/announcement/2025/suse-su-202502042-1/